7.1high
SecMateSECMATE-2026-0004
VendorTuya
Productarduino-TuyaOpen
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
Reported
Feb 22, 2026
Acknowledged
Feb 25, 2026
Fixed
Feb 25, 2026
Published
Mar 12, 2026
Summary
A single-byte (off-by-one) heap overflow vulnerability exists in the WiFiMulti addAP function of arduino-TuyaOpen versions prior to v1.2.1. An attacker can exploit this vulnerability when a victim connects to a malicious AP hotspot, potentially enabling overflow-based code execution on the device firmware.